IN THE CLAIMS 



This listing of claims will replace all prior versions, and listings, of claims in the 
application: 
Listing of Claims: 

1 . (Currently Amended) A method of providing security, comprising: 

accessing a file configured by a proc e ss to store operational information 
associat e d with th e comprising an identification of one or more resources accessed by a 
process during initialization of the process, which file an operating system with which the 
process is associated, or a component or module of the operating system, is configured to 
use in the event of a subsequent initialization of the process to prefetch at least one of 
said one or more resources prior to access to said at least one of said one or more 
resources being requested by the process ; 

determining a first behavior using the operational information, wherein the 
first behavior is associated with the process; 

monitoring the process; comparing a second behavior with the first 
behavior, wherein the second behavior is attempted by the process; and 

performing a predetermined responsive action if the second behavior is 
different from the first behavior; 

wherein th e op e rational information includ e s a list of on e or mor e 
r e sourc e s accessed by th e proc e ss in the course of a normal and permitt e d op e ration; the 
fil e is used by th e proc e ss in th e cours e of said normal and p e rmitt e d op e ration to e nabl e 
th e proc e ss to acc e ss said r e sourc e s and determining the first behavior includes parsing 
the file to identify the one or more resources. 

2. (Previously Presented) The method of providing security as recited in Claim 1, in an 

event the second behavior is determined to be different from the first behavior, the second 
behavior is determined to be disallowed. 

3. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the first behavior is one of a plurality of behaviors determined using the operational information. 
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4. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the first behavior is one of a plurality of behaviors determined using the operational information, 
and in the event the second behavior is determined to be different from the plurality of behaviors, 
the second behavior is determined to be disallowed. 

5. (Previously Presented) The method of providing security as recited in Claim 1, further 
comprising determining that the second behavior is disallowed. 

6. (Previously Presented) The method of providing security as recited in Claim 1, further 
comprising determining that the second behavior is disallowed and performing a predetermined 
action. 

7. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the predetermined action includes preventing the second behavior from succeeding. 

8. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the predetermined action includes generating an event associated with the second behavior. 

9. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
determining the first behavior using the operational information is performed when the process is 
not operating. 

10. (Canceled) 

11. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the operational information includes information is used to improve process initialization time. 

12. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the operational information is configured on a per user basis. 

13. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the operational information includes component access information. 
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14. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the file includes a prefetch file. 

15. (Previously Presented) The method of providing security as recited in Claim 1, wherein 
the file includes a superfetch file. 

16. (Currently Amended) A system for providing security, comprising: 

a processor configured to: 

access a file configured by a proc e ss to store operational 
informatio n associat e d with the comprising an identification of one or more 
resources accessed by a p rocess during initialization of the process, which file an 
operating system with which the process is associated, or a component or module 
of the operating system, is configured to use in the event of a subsequent 
initialization of the process to prefetch at least one of said one or more resources 
prior to access to said at least one of said one or more resources being requested 
by the process ; 

determine a first behavior using the operational information, 
wherein the first behavior is associated with the process; 
monitor the process; 

compare a second behavior with the first behavior, wherein the 
second behavior is attempted by the process; and 

perform a predetermined responsive action if the second behavior 
is different from the first behavior; and 

a memory coupled with the processor, configured to provide the processor 
with directions; 

wherein th e op e rational information includ e s a list of on e or more 
r e sources acc e ss e d by the proc e ss in th e cours e of a normal and p e rmitted operation; th e 
fil e is used by th e proc e ss in th e cours e of said normal and permitt e d operation to e nabl e 
th e proc e ss to acc e ss said r e sources and determining the first behavior includes parsing 
the file to identify the one or more resources. 
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1 7. (Currently Amended) A computer program product for providing security, the computer 
program product being embodied in a computer readable storage m edium and comprising 
computer instructions for: 

accessing a file configured by a proc e ss to store operational information 
associat e d with th e comprising an identification of one or more resources accessed by a 
process during initialization of the process, which file an operating system with which the 
process is associated, or a component or module of the operating system, is configured to 
use in the event of a subsequent initialization of the process to prefetch at least one of 
said one or more resources prior to access to said at least one of said one or more 
resources being requested by the process ; 

determining a first behavior using the operational information, wherein the 
first behavior is associated with the process; 

monitoring the process; 

comparing a second behavior with the first behavior, wherein the second 
behavior is attempted by the process; and 

performing a predetermined responsive action if the second behavior is 
different from the first behavior; 

wherein th e op e rational information includ e s a list of on e or more 
resources acc e ss e d by th e proc e ss in the cours e of a normal and p e rmitt e d op e ration; th e 
file is used by th e proc e ss in th e cours e of said normal and permitt e d op e ration to e nabl e 
th e proc e ss to acc e ss said resourc e s and determining the first behavior includes parsing 
the file to identify the one or more resources. 

18. (Canceled) 

19. (Canceled) 

20. (Canceled) 
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